All incidents

Adobe Acrobat Chrome extension flaw (CVE-2026-48294) enables WhatsApp data theft

vulnerabilityopenJul 22, 2026 — Jul 22, 2026
Adobe Acrobat Chrome flaw exposes WhatsApp Web chats to hijackers

A critical flaw in the Adobe Acrobat Chrome extension, tracked as CVE‑2026‑48294, was disclosed by Guardio Labs, allowing attackers to silently harvest WhatsApp Web chats, contacts and messages by luring users to a malicious webpage. The vulnerability affected roughly 329 million installations of the extension and was patched by Adobe in June after the researcher report. SecurityAffairs was among the first outlets to cover the story, noting the potential for silent data theft without any user interaction beyond visiting a compromised site.

The issue stemmed from three distinct weaknesses in the extension’s messaging infrastructure that let a remote site write arbitrary data into the extension’s storage and then invoke its internal bridge to read WhatsApp Web’s DOM. Because the extension failed to validate the origin of incoming messages, an attacker could craft a specially formed request that triggered the data leak without needing any malware or phishing credentials on the victim’s machine.

Guardio Labs rated the vulnerability at CVSS 7.4, reflecting its high impact and low attack complexity, and noted that versions of the extension released before the June update were vulnerable.

The flaw allowed a malicious page to inject a crafted message that the extension processed as a legitimate internal command, leading to unauthorized read access to the WhatsApp Web interface loaded in the same browser session. SecurityWeek detailed how Adobe’s security advisory confirmed that the patch tightened origin checks and removed the insecure storage write capability that underpinned the exploit. Users running extensions prior to the June 2026 patch remained exposed until they applied the update.

At the time of public disclosure there was no evidence of active exploitation in the wild and no threat actor has been linked to the flaw, but the sheer size of the user base makes it an attractive target for future opportunistic campaigns. The incident highlights how widely deployed browser extensions can become unintended pivot points for data theft when their communication channels are not properly sandboxed. Researchers warned that similar design patterns appear in other productivity extensions that expose privileged APIs to content scripts without adequate origin verification.

This case adds to a growing list of browser‑extension supply‑chain weaknesses where trusted tools are repurposed to harvest sensitive web‑application data, a trend that has been observed in both corporate and consumer environments. It highlights the need for developers to adopt strict message‑validation frameworks and for enterprises to inventory extensions with cross‑origin permissions. Security teams should treat any extension capable of interacting with arbitrary web pages as a potential vector for credential or conversation harvesting.

Organizations should ensure that the Adobe Acrobat Chrome extension is updated to the latest version available from the Chrome Web Store and verify that the update succeeds across all endpoints. Administrators are advised to review the permissions granted to all installed extensions, disable those that are not required for business functions, and consider employing an extension allow‑list to block unknown or unnecessary add‑ons. Users should be reminded to avoid navigating to unfamiliar or suspicious sites even when using trusted extensions, as the exploit relied solely on a malicious web page.

Monitoring web traffic for unexpected POST or GET requests to WhatsApp Web domains can help detect attempted abuse, while endpoint detection solutions should be tuned to flag anomalous DOM access originating from browser extensions. Finally, regular vulnerability‑management cycles that include third‑party extension updates will reduce the window of exposure to similar flaws in the future.

Intelligence briefing updated Jul 22, 2026

CVE-2026-48294 7.4
Root sourceguard.io
Timeline Coverage

Swipe to explore timeline